syncfusion-aspnetcore-tabs
Pass
Audited by Gen Agent Trust Hub on Sep 22, 2026
Risk Level: SAFEEXTERNAL_DOWNLOADSINDIRECT_PROMPT_INJECTION
Full Analysis
- [EXTERNAL_DOWNLOADS]: The skill references and downloads component assets from the official Syncfusion Content Delivery Network (CDN) for styling and functionality.
- Evidence: References to
https://cdn.syncfusion.com/ej2/{{ site.ej2version }}/fluent.cssandhttps://cdn.syncfusion.com/ej2/{{ site.ej2version }}/dist/ej2.min.jsinreferences/getting-started.md. - [INDIRECT_PROMPT_INJECTION]: The skill documents methods for dynamically loading and rendering external HTML content, which represents a potential attack surface for indirect prompt injection if untrusted data is processed.
- Ingestion points: Data ingested through the
contentproperty ofTabItemModeland dynamically viafetchrequests within event handlers likeselectedorcontentLoad(documented inreferences/tab-content-rendering.mdandreferences/advanced-features.md). - Boundary markers: The component uses standard web DOM isolation and manages state through browser-level constructs like
localStorage. - Capability inventory: The examples demonstrate network access via the
fetchAPI and the ability to modify the DOM directly usinginnerHTML. - Sanitization: The Tab component includes a built-in HTML sanitizer (
enableHtmlSanitizer), which is enabled by default to strip potentially malicious code from content before rendering, as detailed inreferences/api-reference.md.
Audit Metadata